Morrow wrote:
>You'd be surprised at how many NCSA httpd sites are
>still out there which are vulnerable to the attack:
You're right, I'm amazed. I've seen variations
on the phf theme everywhere (including this list),
so I would have thought a military organisation
would know better. And how many on this list
do not know of bouncing mails in early versions
of sendmail, or of NFS weaknesses (referring to
Michael J. O'Conner's reply)?
In a way it's comforting to hear that these sites
are accessible to anyone capable of reading COAST,
or any other primer on security - it definitely
must mean that the cold war is really over.
Regards,
Sebastian Stache <<application/ms-tnef>>
|
|